A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13)
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Hmibscea53d1edb
Subscribe
Hmibscea53d1edb Firmware
Subscribe
Hmibscea53d1edl
Subscribe
Hmibscea53d1edl Firmware
Subscribe
Hmibscea53d1edm
Subscribe
Hmibscea53d1edm Firmware
Subscribe
Hmibscea53d1eds
Subscribe
Hmibscea53d1eds Firmware
Subscribe
Hmibscea53d1eml
Subscribe
Hmibscea53d1eml Firmware
Subscribe
Hmibscea53d1esm
Subscribe
Hmibscea53d1esm Firmware
Subscribe
Hmibscea53d1ess
Subscribe
Hmibscea53d1ess Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27951 | A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-03T03:21:49.150Z
Reserved: 2022-01-07T00:00:00
Link: CVE-2022-22808
No data.
Status : Modified
Published: 2022-02-09T23:15:19.243
Modified: 2024-11-21T06:47:29.243
Link: CVE-2022-22808
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD